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WHICHEVER IS LONGER, FROM THE MAILING DATE OF THIS COMMUNICATION. 
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DETAILED ACTION 

1. Claims 1-4, 6, 10, 19, 21, and 22 have been examined. 

Claim Rejections - 35 USC § 102 

2. The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the 
basis for the rejections under this section made in this Office action: 

A person shall be entitled to a patent unless - 

(e) the invention was described in (1) an application for patent, published under section 122(b), by another filed 
in the United States before the invention by the applicant for patent or (2) a patent granted on an application for 
patent by another filed in the United States before the invention by the applicant for patent, except that an 
international application filed under the treaty defined in section 351(a) shall have the effects for purposes of this 
subsection of an application filed in the United States only if the international application designated the United 
States and was published under Article 21(2) of such treaty in the English language. 

3. Claiml-4, 6, 10, 19, 21, 22, and 36-60 are rejected under 35 U.S.C. 102(e) as being 
anticipated by Korn U.S. Pat. No. 6880083 (hereinafter Korn). 

4. As per claim 1 , Korn discloses a method, comprising: a first electronic device deriving a 
digital signature and associating the digital signature with a web page, wherein the web page 
includes code to invoke a control object, and wherein the web page does not include the control 
object (Korn: column 2 lines 39-65: hash value is generated for the script and the hash value is 
further encrypted as a digital signature); and subsequent to associating the digital signature with 
the web page, the first electronic device delivering the web page to a second electronic device 
capable of authenticating the digital signature such that the second electronic device executes at 
least a portion of the web page in response to authenticating the digital signature (Korn: column 
3 lines 50-65: the encrypted hash value is decrypted using the public key and compared to see if 
the script can be executed). 
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5. As per claim 2, Korn discloses the method of claim 1 . Korn further discloses wherein the 
associating further comprises attaching the digital signature to the web page (Korn: column 3 
lines 21-34: the signature is associated with the web page). 

6. As per claim 3, Korn discloses the method of claim 1 . Korn further discloses in an event 
that the web page does not include code to invoke the control object, delivering the web page 
without a digital signature (Korn: column 1 lines 55-59: only the executable commands are 
hashed and encrypted). 

7. As per claim 4, Korn discloses the method of claim 1 . Korn further discloses wherein the 
web page includes a confirmation module that is used by the electronic device to authenticate the 
digital signature (Korn: column 3 lines 7-20: public key associated with the signature may be 
appended to the web page). 

8. As per claim 6, Korn discloses the method of claim 1 . Korn further discloses wherein the 
web page is generated in an active server page environment (Korn: column 2 lines 25-28: HTML 
that allows dynamic invocation of controls). 

9. As per claim 10, Korn discloses the method of claim 1. Korn further discloses 
designating one or more sources of a web page authorized to invoke the control object (Korn: 
column 2 lines 57-62). 
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10. As per claim 19, Korn discloses the method of claim 1. Korn further discloses wherein 
the control object includes a confirmation module configured to authenticate the digital signature 
(Korn: column 3 lines 21-32: the control determines if the script is to be executed). 

11. As per claim 2 1 , Korn discloses the method of claim 1 9. Korn further discloses wherein 
the confirmation module is further configured to determine if the web page comes from a source 
that is authorized to invoke the control object and the control object is invoked only if the source 
of the web page is authorized to invoke the control object (Korn: column 3 lines 50-64: 
determine if the source is authorized to invoke the control object by comparing hash values). 

12. As per claim 22, Korn discloses the method of claim 22. Korn further discloses wherein 
the confirmation module is called by the web page prior to the web page invoking the control 
object (Korn: column 3 lines 50-64). 

13. As per claim 36, Korn discloses a method, comprising: a first electronic device receiving 
from a second electronic device, a request to download a web page (Korn: column 2 lines 39- 
65); and in response to receiving the request, the first electronic device: determining whether the 
web page includes code to invoke a control object; in an event that the web page includes code to 
invoke a control object, associating a web page digital signature with the web page (Korn: 
column 3 lines 1-5); and delivering the web page to the second electronic device, wherein the 
second electronic device is capable of authenticating the web page digital signature such that the 
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second electronic device executes at least a portion of the web page in response to authenticating 
the web page digital signature (Korn: column 3 lines 7-10; column 3 lines 50-64). 

14. As per claim 37, Korn discloses the method of claim 36. Korn further discloses wherein a 
control signature is associated with the control object (Korn: figure 2: 210 verify control 
signature). 

15. As per claim 38, Korn discloses the method of claim 36. Korn further discloses wherein 
associating the web page digital signature with the web page further comprises deriving the web 
page digital signature (Korn: column 2 lines 52-65). 

16. As per claim 39, Korn discloses the method of claim 36. Korn further discloses in an 
event that the web page does not include code to invoke the control object: in response to 
receiving the request, the first electronic device delivering the web page to the second electronic 
device without the web page digital signature (Korn: column 1 lines 55-59: only the executable 
commands are hashed and encrypted). 

1 7. As per claim 40, Korn discloses the method of claim 36. Korn further discloses wherein 
the web page includes a confirmation module that is used by the second electronic device to 
authenticate the web page digital signature (Korn: column 3 lines 10-12: public key may be 
appended to the script as well). 
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18. As per claim 4 1 , Korn discloses the method of claim 36. Korn further discloses wherein 
the control object includes a confirmation module configured to authenticate the web page digital 
signature (Korn: column 3 lines 21-34). 

1 9. As per claim 42 5 Korn discloses the method of claim 36. Korn further discloses wherein 
the confirmation module is further configured to determine if the web page comes from a source 
that is authorized to invoke the control object and the control object is invoked only if the source 
of the web page is authorized to invoke the control object (Korn: column 3 lines 50-64: 
determine if the source is authorized to invoke the control object by comparing hash values). 

20. As per claim 43. Korn discloses the method of claim 36. Korn as modified further 
discloses wherein the confirmation module is called by the web page prior to the web page 
invoking the control object (Korn: column 3 lines 50-64). 

21. As per claim 44-60, claims 44-60 encompass the same scope as claims 1-4, 6, 10, 19, 21, 
22 and 36-43. Therefore, claims 44-60 are rejected based on the same rationale set forth above in 
rejecting claims 1-4, 6, 10, 19, 21, 22 and 36-43. 

Response to Arguments 

22. Applicant's arguments with respect to claims 1-4, 6, 10, 19, 21, 22 and 36-60 have been 
considered but are moot in view of the new ground(s) of rejection. 
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Conclusion 

23. Applicant's amendment necessitated the new ground(s) of rejection presented in this 
Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). 
Applicant is reminded of the extension of time policy as set forth in 37 CFR 1 .136(a). 

A shortened statutory period for reply to this final action is set to expire THREE 
MONTHS from the mailing date of this action. In the event a first reply is filed within TWO 
MONTHS of the mailing date of this final action and the advisory action is not mailed until after 
the end of the THREE-MONTH shortened statutory period, then the shortened statutory period 
will expire on the date the advisory action is mailed, and any extension fee pursuant to 37 
CFR 1 .136(a) will be calculated from the mailing date of the advisory action. In no event, 
however, will the statutory period for reply expire later than SIX MONTHS from the date of this 
final action. 

Any inquiry concerning this communication or earlier communications from the 
examiner should be directed to Shin-Hon Chen whose telephone number is (571) 272-3789. The 
examiner can normally be reached on Monday through Friday 8:30am to 5:30pm. 

If attempts to reach the examiner by telephone are unsuccessful, the examiner's 
supervisor, Ayaz Sheikh can be reached on (571) 272-3795. The fax phone number for the 
organization where this application or proceeding is assigned is 571-273-8300. 
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Information regarding the status of an application may be obtained from the Patent 
Application Information Retrieval (PAIR) system. Status information for published applications 
may be obtained from either Private PAIR or Public PAIR. Status information for unpublished 
applications is available through Private PAIR only. For more information about the PAIR 
system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR 
system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would 
like assistance from a USPTO Customer Service Representative or access to the automated 
information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. 
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